Service Control Policies
Resource Control Policies
Declarative Policies
Tag, Backup & AI Opt-Out Policies
Config Rules
CloudWatch Alarms and Event Rules
CloudFormation Guard Rules
Backups & DR
Configure the infrastructure for a three-tier web application that includes load balancing, EC2 instances and scaling groups, and an optional database tier

Create new VPCs with multiple subnet tier and internet connectivity configurations (or update existing VPCs), and enable common logging and connectivity options

Configure AWS Client VPN to allow direct connectivity to an AWS VPC from users' machines.

Configure AWS Backup to automatically backup AWS resources including EC2, EBS, EFS, DynamoDB, RDS, Aurora, Neptune, and DocumentDB. Supports replica region or account configuration for additional high availability.

Create a CI/CD pipeline to deploy AWS infrastructure using CloudFormation, while ensuring security with an automated inline static security analysis to detect any potential security misconfiguration

Configure essential AWS security logging and monitoring services (with email notifications for findings)

Create a central security account to delegate management of security services in an AWS organization

Set up hub and spoke accounts for a centralized logging architecture in a multi-account environment